Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gx8-6452-hc3w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.

The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.

EPSS

Процентиль: 70%
0.00641
Низкий

Связанные уязвимости

nvd
больше 12 лет назад

The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.

debian
больше 12 лет назад

The RPM GPG key import and handling feature in libzypp 12.15.0 and ear ...

EPSS

Процентиль: 70%
0.00641
Низкий